Reference · built on requestOperator by FibricWorkforce & scheduling

Punch Match

Compares clock punches with badge, login, or agent-state records and proposes manager review where a punch has no matching presence.

About

Punch Match is an operator job for the question a timesheet cannot answer on its own: was the person there? It reads each punch from your time and attendance system and looks for a matching record of presence in the systems a shift leaves traces in. For a site, that is a badge read at a door. For a desk, a sign-in at your identity provider. For a contact center, an agent LOGIN event or a routable status in Amazon Connect.

A punch with no presence record inside the window you set is queued for the employee's manager with the records it did find. The manager reviews it, marks it explained or disputed, and the outcome is kept against the punch. The operator writes nothing to the time system itself.

This is a reference listing. It documents what Fibric would read from Punch Match and what it could propose, based on the vendor's published interfaces. Fibric builds it under a managed deployment when you request it; selecting it here installs nothing.

Inputs

  • Punches with clock-in and clock-out: 7shifts time_punches, Deputy Timesheet records, QuickBooks Time timesheets, Dayforce EmployeePunches by transaction time
  • Badge reads by site and time: Brivo access events, Verkada access events with user_id and credential, Genea access events by user and card number
  • Sign-ins: Okta System Log events such as user.session.start, Microsoft Entra ID sign-in records, Google Workspace users with lastLoginTime
  • Agent presence: Amazon Connect agent event streams with LOGIN, LOGOUT, and STATE_CHANGE events and an AgentStatus with StartTimestamp; Genesys Cloud routing status
  • Punch history where the system keeps it: When I Work time history with punch type, method, and alert_type
  • The site, device, or queue each employee is expected at, taken from the scheduled shift

Proposed actions

  • Target capability: propose a manager review of a punch with no matching presence, showing the punch and the records searched
  • Target capability: propose a note on the punch or timesheet recording the outcome, where the time system accepts one
  • Target capability: propose a daily summary per site or team of matched, unmatched, and explained punches
  • Target capability: propose a message to the manager in Slack or Microsoft Teams with the reviews waiting

Proposed actions are target capabilities. Every action runs propose-first and needs a validated deployment and the appropriate permissions.

What you can build

  • Match Deputy timesheets to Brivo badge reads

    Each timesheet is paired with access events at the site inside the window you set. Unmatched timesheets go to the area manager in Slack with the door events that were found.

    With Deputy, Brivo Access, Slack

  • Check contact center punches against Amazon Connect

    QuickBooks Time timesheets are compared with agent event streams: a LOGIN before the clock-in and a ROUTABLE status during the shift count as presence. A punch with neither is queued for review.

    With QuickBooks Time, Amazon Connect

  • Use Okta sign-ins for remote staff

    For employees with no site, user.session.start events from the System Log stand in for a badge. A 7shifts punch with no session that day is proposed for review in Microsoft Teams.

    With 7shifts, Okta, Microsoft Teams

  • Compare Dayforce punches with Verkada

    EmployeePunches by transaction time are matched to Verkada access events by user_id. The operator proposes a daily summary per location and queues the unmatched punches.

    With Dayforce, Verkada

Requirements

  • Punches from a time and attendance connector such as 7shifts, Deputy, QuickBooks Time, When I Work, or Dayforce
  • At least one presence source: an access control connector, an identity connector, or a contact center connector
  • An identity mapping between the time system and each presence source, kept by the operator and reviewed by you
  • Slack or Microsoft Teams, or the time system's notes, for the manager's review
Authentication
Each system is read through the connector you bind to it, with that connector's access; the operator asks for no credentials of its own.

Limits

  • A missing record is not proof of absence. A propped door, a shared terminal, or a sign-in that outlived the shift all leave gaps
  • Okta returns no System Log data older than 90 days, and Brivo access events are read in windows of at most 24 hours
  • Amazon Connect keeps publishing HEART_BEAT events for up to an hour after logout; the operator reads LOGIN, LOGOUT, and STATE_CHANGE, not heartbeats
  • It reads presence; it does not create it. Nothing is written to access control, identity, or the contact center

Access and pricing

Reference listing. Fibric builds the operator under a managed deployment when you request it. Your quote covers the build, capabilities, usage, and support.

Request Punch Match ↗

Questions and answers

What does the manager review?
A punch, the shift it belongs to, the window searched, and every presence record found in it, or none. The manager marks the punch explained or disputed and can add a reason. The punch itself is not changed.
What is written down for an unmatched punch?
For each unmatched punch: the sources searched, the records found, the manager's outcome with time and name, and the identity mapping used. The record stays with the punch through the pay period.
Does it change a timesheet or block pay?
No. It proposes a review and, where the time system accepts notes, a note. Editing a punch, approving a timesheet, and paying it are still done by people in those systems.
Ask about Punch Match

Ask about the capabilities and requirements in this listing.

For project-specific requirements, contact Fibric.